这段关于 MongoDB C 驱动中 TLS 传输层堆溢出漏洞的描述,可以翻译如下: 参考译文: 在基于 Windows 平台 TLS 后端编译的 MongoDB C 驱动中,TLS 传输层存在堆缓冲区溢出漏洞。客户端连接的远程端点,或能够冒充或重定向客户端连接的攻击者,可以在处理传入的加密流量时,导致驱动将攻击者提供的数据写到堆分配内存的边界之外。由于受影响的处理发生在应用层认证完成之前,因此无需身份验证或用户交互。成功利用该漏洞可能导致客户端进程中的内存损坏、相邻堆内存泄露,或导致进程终止。 --- 术语与细节
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB Inc. | C Driver | 2.4.0 |
affected |
2.3.0≤ 2.3.3 |
affected | ||
2.2.0≤ 2.2.4 |
affected | ||
2.1.0≤ 2.1.2 |
affected | ||
2.0.0≤ 2.0.2 |
affected | ||
1.30.0≤ 1.30.8 |
affected | ||
1.29.0≤ 1.29.2 |
affected | ||
1.28.0≤ 1.28.1 |
affected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | C Driver | 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92756 | 5.5 MEDIUM | Combining encryption settings may disable encryption |
| CVE-2026-92757 | 5.5 MEDIUM | Malformed connection string may disable field level encryption |
| CVE-2026-92758 | 5.5 MEDIUM | Logs may collect sensitive information |
| CVE-2026-93395 | 5.3 MEDIUM | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
| CVE-2026-93394 | 3.7 LOW | libmongoc SCRAM client nonce-validation bypass |
No comments yet